06 Wrz 2011, 19:00
06 Wrz 2011, 20:47
:OTL
MOD - [2011-09-06 15:10:52 | 000,026,624 | ---- | M] () -- C:\WINDOWS\system32\dll.dll
SRV - File not found [On_Demand | Stopped] -- -- (WPFFontCache_v0400)
SRV - File not found [Auto | Stopped] -- -- (czemgwslq)
O4 - HKU\S-1-5-21-842925246-1454471165-839522115-1003..\Run: [] File not found
O20 - Winlogon\Notify\cryptnet32: DllName - cryptnet32.dll - C:\WINDOWS\System32\cryptnet32.dll ()
[2011-09-06 15:10:53 | 000,000,016 | ---- | M] () -- C:\WINDOWS\System32\crt.dat
O33 - MountPoints2\{c7a60250-a5d8-11df-b7eb-8216ad039ec8}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe
O33 - MountPoints2\{c7a60250-a5d8-11df-b7eb-8216ad039ec8}\Shell\Open(&0)\command - "" = Recycled\ctfmon.exe
O33 - MountPoints2\{fea9e84d-a655-11e0-b8ee-ac218c3a9de7}\Shell - "" = AutoRun
:Reg
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ALLUpdate"=-
:Commands
[clearallrestorepoints]
[emptytemp]
06 Wrz 2011, 21:32
07 Wrz 2011, 18:44
:OTL
O20 - Winlogon\Notify\cryptnet32: DllName - cryptnet32.dll - File not found
O33 - MountPoints2\{9107891c-a5d0-11df-b7e7-89d6f704b7c5}\Shell - "" = AutoRun
O33 - MountPoints2\{9107891c-a5d0-11df-b7e7-89d6f704b7c5}\Shell\AutoRun\command - "" = F:\setup.exe AUTORUN=1
O33 - MountPoints2\{c7a60250-a5d8-11df-b7eb-8216ad039ec8}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe
O33 - MountPoints2\{c7a60250-a5d8-11df-b7eb-8216ad039ec8}\Shell\Open(&0)\command - "" = Recycled\ctfmon.exe
[2011-09-06 21:16:00 | 000,001,036 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011-09-06 21:03:40 | 000,001,032 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
:Files
C:\WINDOWS\System32\dll.dll
C:\WINDOWS\System32\shimg.dll
C:\WINDOWS\System32\drivers\str.sys
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Alcmtr"=-
[HKEY_USERS\S-1-5-21-842925246-1454471165-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=-
:Commands
[clearallrestorepoints]
[emptytemp]
08 Wrz 2011, 20:01
08 Wrz 2011, 20:13
:OTL
O33 - MountPoints2\{9107891c-a5d0-11df-b7e7-89d6f704b7c5}\Shell - "" = AutoRun
O33 - MountPoints2\{9107891c-a5d0-11df-b7e7-89d6f704b7c5}\Shell\AutoRun\command - "" = F:\setup.exe AUTORUN=1
O33 - MountPoints2\{c7a60250-a5d8-11df-b7eb-8216ad039ec8}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe
O33 - MountPoints2\{c7a60250-a5d8-11df-b7eb-8216ad039ec8}\Shell\Open(&0)\command - "" = Recycled\ctfmon.exe
[2011-09-08 19:45:05 | 000,000,628 | ---- | M] () -- C:\WINDOWS\tasks\SymInstallStub.job
@Alternate Data Stream - 943 bytes C:\Documents and Settings\All Users\Dane aplikacji\TEMP:24721E3C
:Commands
[clearallrestorepoints]
[emptytemp]
08 Wrz 2011, 20:47
08 Wrz 2011, 20:52
:Services
killallprocesses
:OTL
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
:Commands
[clearallrestorepoints]
[emptytemp]
08 Wrz 2011, 21:25
09 Wrz 2011, 16:01
Java(TM) 6 Update 17
Adobe Reader 9.4.5 - Polish
12 Wrz 2011, 09:59